CVE-2024-56344: IBM Cognos Analytics 12.0.4 and 12.1.3 versions are affected by security vulnerabilities
IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.3 FP1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
Other sources
IBM Cognos Analytics could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Cognos Analyticsto a version that resolves this vulnerability.Fixed in 12.0.4 FP3 - Upgrade
Upgrade
IBM Cognos Analyticsto a version that resolves this vulnerability.Fixed in 12.1.3 FP2 - Configuration
Enable HTTP Strict Transport Security (HSTS) in IBM Cognos Analytics to address the issue where HTTP Strict Transport Security was not properly enabled (affected ranges: 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.3 FP1).
IBM Cognos Analytics HTTP Strict Transport Security (HSTS) = Properly enable HSTS - Compensating control
Use a network-layer man-in-the-middle mitigation (e.g., enforce HTTPS with strong certificate validation and/or restrict access paths so attackers cannot intercept connections) until the fixed IBM Cognos Analytics releases (12.0.4 FP3, 12.1.3 FP2) are applied.